GRCGuideline

CPG 235

Prudential Practice Guide CPG 235 - Managing Data Risk

The Prudential Practice Guide CPG 235 provides guidance for Australian financial institutions on how to effectively manage data risk. It focuses on identifying, assessing, and mitigating risks associated with data to ensure its integrity, availability, and confidentiality.

Overview

The Prudential Practice Guide CPG 235, published by the Australian Prudential Regulation Authority (APRA), aims to help regulated financial institutions develop robust strategies for managing risks tied to their data assets. The guide emphasizes the importance of data management frameworks, risk assessments, and operational controls in safeguarding data integrity, availability, and confidentiality. While not a prescriptive standard, it serves as an advisory guide to align data risk management practices with prudential standards and regulatory expectations. Key themes include governance, accountability, and embedding effective controls. Institutions are encouraged to consider their size, complexity, and risk profile when implementing recommendations from this guide.

Related in GRC

GRCFramework

COBIT 5 β€” COBIT 5

COBIT 5 is a comprehensive framework for the governance and management of enterprise IT, designed to maximize the value organizations derive from their information systems. It incorporates principles, practices, and tools to align IT with business strategies and goals.

ISACA β€’ Global β€’ v5

View details
GRCLaw

Sex Discrimination Act 1984

A federal law enacted by the Australian Government to eliminate discrimination on the basis of sex, gender identity, sexual orientation, marital status, pregnancy, or family responsibilities. It also addresses sexual harassment and outlines protections in employment, education, goods and services, and public programs.

Attorney-General's Department β€’ Australia β€’ v1 January 2014

View details
GRCLaw

South Africa Electronic Communications and Transactions Act 25 of 2002

The Electronic Communications and Transactions Act 25 of 2002 establishes legal and policy frameworks for regulating electronic communications and transactions in South Africa. It aims to facilitate universal access to electronic services, prevent abuse of information systems, and promote the use of e-government services and small business technology adoption.

Government of South Africa β€’ South Africa

View details
GRCLaw

Trade Marks Act 1995

The Trade Marks Act 1995 is an Australian legislation that governs the registration, use, protection, and enforcement of trade marks within the country. It provides rules for registering trade marks, handling disputes, managing trade mark rights, and addressing infringements.

Department of Industry, Science and Resources β€’ Australia β€’ vCompilation No. 38, 24 February 2019

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks β€” automatically.

Book your strategy call